[root@YMM tmp]# cat /etc/passwd|grep elog_user
elog_user:x:502:503::/home/Unicom/elogDir:/sbin/nologin
[root@YMM tmp]# netstat |grep ftp
tcp 0 0 172.168.1.155:50750 172.168.1.161:ftp ESTABLISHED
tcp 0 0 172.168.1.155:ftp 172.168.1.154:51981 TIME_WAIT
tcp 0 0 172.168.1.155:ftp 172.168.1.154:51977 TIME_WAIT
tcp 0 0 172.168.1.155:ftp 172.168.1.154:51979 TIME_WAIT
tcp 0 0 172.168.1.155:ftp 172.168.1.168:57437 TIME_WAIT
tcp 0 0 172.168.1.155:ftp 172.168.1.168:57425 TIME_WAIT
10:40:40.629789 IP 172.168.1.154.51627 > 172.168.1.155.21: Flags [P.], seq 1:17, ack 21, win 115, options [nop,nop,TS val 1804049752 ecr 1800293869], length 16
0x0000: 4500 0044 38a6 4000 4006 7d88 c0a8 019a E..D8.@.@.}.....
0x0010: c0a8 019b c9ab 0015 b4cf a5f7 16cd ee1b ................
0x0020: 8018 0073 8f56 0000 0101 080a 6b87 9d58 ...s.V......k..X
0x0030: 6b4e 4ded 5553 4552 2065 6c6f 675f 7573 kNM.USER.elog_us
0x0040: 6572 0d0a er..
10:40:40.629804 IP 172.168.1.155.21 > 172.168.1.154.51627: Flags [.], ack 17, win 114, options [nop,nop,TS val 1800293869 ecr 1804049752], length 0
0x0000: 4500 0034 a3ee 4000 4006 1250 c0a8 019b E..4..@[email protected]....
0x0010: c0a8 019a 0015 c9ab 16cd ee1b b4cf a607 ................
0x0020: 8010 0072 0629 0000 0101 080a 6b4e 4ded ...r.)......kNM.
0x0030: 6b87 9d58 k..X
[root@YMM tmp]# grep -B 4 "elog_us" a.log
10:40:30.397662 IP 172.168.1.154.51625 > 172.168.1.155.21: Flags [P.], seq 1:17, ack 21, win 115, options [nop,nop,TS val 1804039520 ecr 1800283637], length 16
0x0000: 4500 0044 3673 4000 4006 7fbb c0a8 019a E..D6s@.@.......
0x0010: c0a8 019b c9a9 0015 a6bc 432e f08c e246 ..........C....F
0x0020: 8018 0073 823a 0000 0101 080a 6b87 7560 ...s.:......k.u`
0x0030: 6b4e 25f5 5553 4552 2065 6c6f 675f 7573 kN%.USER.elog_us
--
10:40:40.629789 IP 172.168.1.154.51627 > 172.168.1.155.21: Flags [P.], seq 1:17, ack 21, win 115, options [nop,nop,TS val 1804049752 ecr 1800293869], length 16
0x0000: 4500 0044 38a6 4000 4006 7d88 c0a8 019a E..D8.@.@.}.....
0x0010: c0a8 019b c9ab 0015 b4cf a5f7 16cd ee1b ................
0x0020: 8018 0073 8f56 0000 0101 080a 6b87 9d58 ...s.V......k..X
0x0030: 6b4e 4ded 5553 4552 2065 6c6f 675f 7573 kNM.USER.elog_us
扩展阅读: http://www.52souji.net/how-to-obtain-some-lines-before-or-after-a-specified-string-in-linux/ 获取特定字符串前后几行数据
http://zebozhuang.blog.163.com/blog/static/17147980420128913935138/ tcpdump抓包的时候,指定网卡